Visual support for analyzing network traffic and intrusion detection events using TreeMap and graph representations
Author(s) -
Florian Mansmann,
Fabian Fischer,
Daniel A. Keim,
Stephen C. North
Publication year - 2009
Publication title -
kops (university of konstanz)
Language(s) - English
Resource type - Conference proceedings
DOI - 10.1145/1641587.1641590
Subject(s) - computer science , intrusion detection system , visualization , graph , network forensics , representation (politics) , data mining , network security , enhanced data rates for gsm evolution , host (biology) , data visualization , distributed computing , theoretical computer science , computer network , artificial intelligence , computer security , digital forensics , law , ecology , biology , politics , political science
Network security depends heavily on automated Intrusion Detection Systems (IDS) to sense malicious activity. Unfortunately, IDS often deliver both too much raw information, and an incomplete local picture, impeding accurate assessment of emerging threats. We propose a system to support analysis of IDS logs, that visually pivots large sets of Net-Flows. In particular, two visual representations of the flow data are compared: a TreeMap visualization of local network hosts, which are linked through hierarchical edge bundles with the external hosts, and a graph representation using a force-directed layout to visualize the structure of the host communication patterns. Three case studies demonstrate the capabilities of our tool to 1) analyze service usage in a managed network, 2) detect a distributed attack, and 3) investigate hosts in our network that communicate with suspect external IPs.
Accelerating Research
Robert Robinson Avenue,
Oxford Science Park, Oxford
OX4 4GP, United Kingdom
Address
John Eccles HouseRobert Robinson Avenue,
Oxford Science Park, Oxford
OX4 4GP, United Kingdom